NIS2 Registration: The Obligation 10,000 German Entities Still Have Not Met

Germany's BSI expected roughly 30,000 entities to register under the NIS2 implementation act. By the statutory deadline of 6 March 2026, about 11,500 had done it. By the end of May, roughly 18,500. That leaves more than 10,000 organisations that are legally in scope, legally required to register, and have not.
The BSI's response was not a fine. It was a second date: 31 July 2026. Not a new statutory deadline — the legal one already passed — but a public signal that after July, the leniency ends.
If you run an MSP or a consultancy with German clients, that date is eleven days away. And registration is the one obligation you cannot fix in a sprint after the fact, because the register is timestamped.
Registration is a separate obligation from Article 21, and it lands first
Most compliance conversations start with the security measures. Risk analysis, incident handling, backups, MFA, supply chain. Article 21 work.
Registration sits somewhere else entirely. It comes from Article 3(4) of NIS2, which requires member states to establish a list of essential and important entities, and from Article 27, which requires certain digital infrastructure entities to submit identifying data. Member states operationalise this by making the entity register itself.
The practical difference matters: Article 21 obligations are assessed over time, in an audit, with room to show progress. Registration is binary. You are in the register on a given date, or you are not.
That is why registration is the first thing a supervisory authority looks at. It costs the regulator nothing to run a query against the register and compare it to a sector list from the chamber of commerce. Unregistered entities are the cheapest enforcement target in the whole directive.
Every member state runs its own register, on its own clock
There is no EU-wide NIS2 registration portal. Each transposition creates its own register, its own portal, and its own deadline — and those deadlines are now spread across a two-year window.
Germany: the NIS2UmsuCG took effect 6 December 2025, the BSI portal opened 6 January 2026, the statutory registration deadline was 6 March 2026, and the enforcement grace period runs to 31 July 2026.
Belgium: registration with the Centre for Cybersecurity Belgium via Safeonweb@work closed on 18 March 2025. Belgium transposed early, so Belgian entities that only started NIS2 work in 2026 are already more than a year late.
The Netherlands: the Eerste Kamer adopted the Cyberbeveiligingswet on 7 July 2026. It enters into force on 15 August 2026, and registration via the NCSC entity register becomes mandatory from that date. Roughly 8,000 Dutch organisations are expected to fall in scope, supervised by the RDI across nine sectors.
Italy: registration under Legislative Decree 138/2024 runs through the ACN portal on an annual cycle, with a defined window each year rather than a one-off deadline.
For an MSP with clients in four countries, that is four portals, four legal bases, four sets of required data fields, and four dates. There is no version of this where a single spreadsheet column called "NIS2: yes/no" is enough.
NIS2 Implementation Status by Country (2025–2026)
Fully in force
BelgiumCroatiaHungaryLithuaniaLatviaItaly6 countriesAdopted — late 2025
GermanyCzech RepublicFinland3 countriesIn progress — expected 2026
NetherlandsFranceSpainPolandAustriaSwedenIreland7 countries
Your client's registration status is your problem before it is theirs
Here is the pattern we keep seeing. An MSP does solid technical work for a client — segmentation, EDR rollout, backup testing, MFA on everything that will take it. Twelve months of genuine security improvement.
Then the supervisory authority contacts the client, and the first question is not about MFA. It is: why are you not in the register?
The client's answer, almost always: "I assumed our IT provider handled that."
They are wrong about the legal position. Registration is the entity's own obligation and cannot be delegated away — the management body carries it under Article 20. But being legally right does not help you when a client's board is asking why nobody flagged it.
The fix is procedural, not technical. For every client, you need three data points on record: whether they are in scope, in which member states, and whether registration is confirmed with a reference number and date. If a client is out of scope, that determination needs to be written down with the reasoning — headcount, turnover, sector under Annex I or II — because "we decided they were out of scope" is not a defence unless you can show the assessment.
Does NIS2 Apply to Your Organisation?
1Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?
Yes▼No▼2Does your organisation have 50 or more employees, or an annual turnover exceeding €10 million?
✗NIS2 does not directly apply to your organisation.
Yes▼No▼✓NIS2 applies to your organisation as an Essential or Important Entity.
3Is your organisation a critical infrastructure provider or a qualified trust service provider?
Yes▼!NIS2 may apply to your organisation — seek legal advice to confirm your status.
1Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?
Yes ↓No →2Does your organisation have 50 or more employees, or an annual turnover exceeding €10 million?
Yes ↓No →3Is your organisation a critical infrastructure provider or a qualified trust service provider?
Yes ↓No →✗NIS2 does not directly apply to your organisation.
✓NIS2 applies to your organisation as an Essential or Important Entity.
!NIS2 may apply to your organisation — seek legal advice to confirm your status.
AppliesPossibly appliesDoes not apply
The scope call is harder than it looks, and defaults toward "in"
Two things push more entities into scope than most consultants expect.
First, the size-cap rule is not the only route in. An entity below 50 staff and €10 million turnover is normally out — but Article 2(2) pulls specific entities in regardless of size, including sole providers of a critical service in a member state, certain DNS and TLD entities, trust service providers, and public administration entities. Germany's transposition has been read broadly here, which is part of why the expected population landed near 30,000.
Second, group structures. Headcount and turnover thresholds are assessed with linked and partner enterprises included, following the EU SME definition. A 30-person Dutch subsidiary of a 900-person group is not a small entity for NIS2 purposes. We see this misread constantly, and it is the single most common reason an entity that believed it was out of scope receives a letter.
If you are running this determination across a client base, do it once, properly, and document it. A structured gap analysis makes the scope call defensible instead of a matter of opinion. You can start that in about ten minutes with our free quick scan, then take the output into a full assessment.
What happens after the grace period is not just a fine
The German framework allows administrative fines up to €10 million or 2% of worldwide annual turnover for essential entities, whichever is higher. That number gets the headlines. It is rarely the thing that actually hurts.
Failure to register is an administrative offence that puts an entity on a supervisory authority's list as a known non-compliant party. That triggers a different posture: the authority now has a reason to look, and once it looks, it looks at Article 21 too. A registration failure is not an isolated penalty — it is an invitation to a full inspection of security measures the entity has likely not finished implementing.
Then it moves down the chain. Registration status is increasingly turning up in supplier due-diligence questionnaires under Article 21(2)(d). An unregistered supplier is a documented supply-chain risk for every essential entity it serves, which means the commercial consequence arrives before the regulatory one. Contract renewals get harder. New tenders get lost.
NIS2 Penalty Escalation — Beyond the Fine
!Trigger event
Non-Compliance Detected or Incident Occurs
A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements
Authorities can impose▼Non-Monetary Penalties1Compliance orders with binding deadlines
2Mandatory security audits at your expense
3Public disclosure of violations
4Binding instructions on specific security measures
Escalates to▼Operational & Personal Consequences1Suspension of certifications or operating licences
2Temporary ban on management functions for individuals
3Public naming of responsible natural persons
TriggerNon-monetaryOperational / personal
What to do in the next eleven days
For German clients specifically, in this order.
Confirm scope. Sector under Annex I or II, size including group entities, and any Article 2(2) override. Write down the answer either way.
Check the register. If a client believes they registered, verify the confirmation and keep the reference. Registrations submitted with incomplete data have been bounced back, and some clients never noticed.
Register before 31 July. The BSI portal has been live since January. The submission itself takes under an hour once you have the entity data, contact points, and sector classification ready. There is no reason to be in the 10,000.
For Dutch clients: 15 August is your date. The register goes live with the law. Get the entity data assembled now, because registering in week one is trivially easy and registering in month four is a conversation with the RDI.
For everyone else: build the register status column into your client tracker permanently. Registration is not a one-time task. Entity data changes, contact points change, and most member states require you to keep the register current — which means the obligation renews every time your client restructures, moves headquarters, or changes their security contact.
The organisations that get caught in the first enforcement wave will not be the ones with imperfect Article 21 controls. Almost nobody has perfect Article 21 controls yet. They will be the ones a regulator could identify with a single database query.
Related reading: NIS2 enforcement in Germany, the Dutch Cyberbeveiligingswet explained, and does NIS2 apply to me.
